The Mail Slot Leads to the Master Key: A cPanel Catastrophe for the Entire Pasture
I want you to sit with this for a moment.
A single lamb, given only the modest privilege of handling the farm's mail, can now unlock the main gate, walk into the shepherd's private quarters, and rewrite every rule on the property. That is not a metaphor for corporate dysfunction, though it certainly applies there too. That is the literal architectural reality of this cPanel vulnerability, and I am genuinely struggling to keep my composure.
The flaw lives in something called EmailTrack. An authenticated account holder with mail-related privileges can use it to write arbitrary files to the server. From there, they escalate to root. Full root. The entire server, every tenant, every account, every secret the machine holds, all of it, handed over like a complimentary welcome basket.
Every supported version of cPanel and WHM is affected. Every. Single. One.
In the old days, privilege separation was a religion. You did not give the mail clerk a key to the vault. You barely gave him a chair. We enforced boundaries with the grim dedication of men who had personally watched systems collapse because someone got lazy. We used physical tape drives. We used discipline.
Now the Flock is running shared hosting environments where a single EmailTrack misconfiguration becomes a master skeleton key, and the Shepherds are presumably off attending a cloud migration webinar, blissfully unaware that a Wolf just strolled through the mail slot.
cPanel published their advisory on September 8th and patched the issue. Credit where it is due, they moved. But the hole in the fence existed, and it existed in production, and that is the part that should keep you awake at night. It keeps me awake. I was already awake, frankly, but now I have a reason.
The Sky Pasture crowd will say this is fine because their infrastructure is "isolated." I have heard that before. I did not believe it then either.
Remediation
I will keep this brief because the fix is not complicated, it is just embarrassing that it is necessary.
Update cPanel and WHM immediately. Not this afternoon. Not after your stand-up. Now. Apply the shearing, dip the flock, and do not leave a single unpatched instance running in your environment.
Audit mail-related privileges across all hosting accounts. If a lamb does not need mail privileges, remove them. Minimum necessary access is not a suggestion, it is the foundational principle that apparently needs to be tattooed somewhere visible.
Review file write permissions on your server. If EmailTrack could write files to sensitive locations, your permission model needs a serious review by someone who remembers why permission models were invented.
The patch exists. Use it. Your excuses do not patch anything.
Stay paranoid out there, the fence is never as solid as you think it is.
Original Report: https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html